Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
INSIGNON.EXE
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
C:\Users\user\Desktop\ImcSys.log
|
ASCII text, with very long lines (728), with CRLF line terminators
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\INSIGNON.EXE
|
"C:\Users\user\Desktop\INSIGNON.EXE"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://Icons.Tritech.com/customericons
|
unknown
|
||
http://maps.google.com/mapfiles/kml
|
unknown
|
||
http://maps.google.com/mapfiles/ms/micons
|
unknown
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
fp2e7a.wpc.phicdn.net
|
192.229.211.108
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
2D6F000
|
stack
|
page read and write
|
||
2F6F000
|
stack
|
page read and write
|
||
55B000
|
unkown
|
page readonly
|
||
22BE000
|
stack
|
page read and write
|
||
738000
|
heap
|
page read and write
|
||
2C68000
|
heap
|
page read and write
|
||
723000
|
heap
|
page read and write
|
||
23A0000
|
trusted library allocation
|
page read and write
|
||
6DE000
|
heap
|
page read and write
|
||
6FB000
|
heap
|
page read and write
|
||
31AF000
|
stack
|
page read and write
|
||
710000
|
heap
|
page read and write
|
||
706000
|
heap
|
page read and write
|
||
2BE0000
|
heap
|
page read and write
|
||
32EF000
|
stack
|
page read and write
|
||
227E000
|
stack
|
page read and write
|
||
610000
|
heap
|
page read and write
|
||
2330000
|
heap
|
page read and write
|
||
650000
|
trusted library allocation
|
page execute read
|
||
619000
|
heap
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
6D0000
|
heap
|
page read and write
|
||
6F0000
|
heap
|
page read and write
|
||
620000
|
heap
|
page read and write
|
||
2C60000
|
heap
|
page read and write
|
||
31EE000
|
stack
|
page read and write
|
||
644000
|
heap
|
page read and write
|
||
22FE000
|
stack
|
page read and write
|
||
737000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
640000
|
heap
|
page read and write
|
||
556000
|
unkown
|
page read and write
|
||
2380000
|
heap
|
page read and write
|
||
70B000
|
heap
|
page read and write
|
||
19A000
|
stack
|
page read and write
|
||
5BE000
|
stack
|
page read and write
|
||
735000
|
heap
|
page read and write
|
||
99F000
|
stack
|
page read and write
|
||
710000
|
heap
|
page read and write
|
||
2AE0000
|
heap
|
page read and write
|
||
4980000
|
trusted library allocation
|
page read and write
|
||
670000
|
heap
|
page read and write
|
||
2E6F000
|
stack
|
page read and write
|
||
625000
|
heap
|
page read and write
|
||
55B000
|
unkown
|
page readonly
|
||
723000
|
heap
|
page read and write
|
||
6F0000
|
heap
|
page read and write
|
||
1F0000
|
heap
|
page read and write
|
||
718000
|
heap
|
page read and write
|
||
2390000
|
heap
|
page read and write
|
||
99000
|
stack
|
page read and write
|
||
723000
|
heap
|
page read and write
|
||
6FE000
|
heap
|
page read and write
|
||
615000
|
heap
|
page read and write
|
||
680000
|
heap
|
page read and write
|
||
2C2E000
|
stack
|
page read and write
|
||
739000
|
heap
|
page read and write
|
||
716000
|
heap
|
page read and write
|
||
570000
|
heap
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
706000
|
heap
|
page read and write
|
||
723000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
6DA000
|
heap
|
page read and write
|
||
A9F000
|
stack
|
page read and write
|
||
71A000
|
heap
|
page read and write
|
||
5FE000
|
stack
|
page read and write
|
There are 57 hidden memdumps, click here to show them.